Infrastructure Suite

Continuous Precision Deployment

Each hospital receives one isolated HMIS deployment. Production traffic follows Browser → Cloudflare (DNS/TLS/WAF) → host Nginx → PM2 on localhost (hmis-web :3000, hmis-api :4000), not direct PM2 ports on the public internet.

Edge before origin

Zone proxy

Public HTTPS terminates at Cloudflare before origin Nginx. Incident response may block ASNs at the edge (docs/info/policies/INCIDENT-RESPONSE-POLICY.md).

Turnstile

Public write routes use Cloudflare Turnstile (TURNSTILE_SECRET, NEXT_PUBLIC_TURNSTILE_SITE_KEY). Login stays rate-limited only.

Real client IP

Install infra/nginx/cloudflare-real-ip.conf so Nginx restores CF-Connecting-IP. Keep TRUST_PROXY=1 on the API.

API Shield (optional)

Upload api/openapi/openapi.cloudflare.json via npm run export:openapi-cloudflare for high-risk /api/v1 schema validation.

Cloudflare Tunnel, R2, and Workers are not documented as required HMIS production components unless your hospital adds them outside this repo.

Delivery pipeline

01

Validate

npm run test:deploy — TypeScript, drift guards, permission catalog, regression.

02

Synthesize

API + web builds, schema extract, app version codegen, Next.js staging swap.

03

Migrate

npx prisma migrate deploy — never rotate JWT/ENCRYPTION secrets casually.

04

Ignite

bash scripts/deploy-pm2.sh — PM2 api, worker, scheduler, web.

Operational commands

high riskbash scripts/deploy-pm2.sh

Canonical production deploy from repo root

medium risknpm run test:deploy

Full deploy gate before release

medium risknpx prisma migrate deploy

Apply pending schema migrations

low riskpm2 status

Instance health and log tail

Runtime stack

PM2 on host; Docker Compose for Postgres, Redis, MongoDB, and observability on localhost

Application processes

  • Node.js≥20 LTS (engines in package.json)
  • OrchestrationPM2 cluster mode
  • Processeshmis-api, hmis-worker, hmis-scheduler, hmis-web
  • Origin proxyinfra/nginx/nginx.conf

Data plane

  • OLTPPostgreSQL 16 (Compose)
  • ChatMongoDB (Compose)
  • Cache / jobsRedis + BullMQ
  • MediaS3-compatible private buckets
  • Pooling (optional)Compose pooler profile, PgBouncer :6432

Emergency shutdown

Enable disaster mode via governance settings and follow docs/info/policies/INCIDENT-RESPONSE-POLICY.md. Production deploy: bash scripts/deploy-pm2.sh from repo root.

Repository documentation

  • docs/info/SECURITY-HARDENING.md
  • docs/info/DR-PLAYBOOK.md
  • docs/info/PERFORMANCE.md
  • docs/info/OBSERVABILITY.md
  • docs/info/SSO-OPERATIONS.md
  • infra/README.md